Skip to content

chore: package and CI maintenance for 0.4.9 - #7

Merged
3leapsdave merged 1 commit into
mainfrom
release/v0.4.9-package-cicd
Jul 29, 2026
Merged

chore: package and CI maintenance for 0.4.9#7
3leapsdave merged 1 commit into
mainfrom
release/v0.4.9-package-cicd

Conversation

@3leapsdave

@3leapsdave 3leapsdave commented Jul 29, 2026

Copy link
Copy Markdown
Member

Summary

Maintenance release prep for 0.4.9: toolchain and dependency refresh, CI/release pin hygiene, bootstrap trust-anchor repair, and release docs.

Changes

  • Raise the secure Go floor to 1.25.12 and preferred toolchain to 1.26.5 (CI/release setup-go aligned).
  • Bump selected modules: golang.org/x/crypto, golang.org/x/sys, golang.org/x/text.
  • Pin goneat v0.5.15 across Makefile and CI dogfood installs (minisign-verified install path).
  • Add pinned govulncheck@v1.6.0 to make precommit (zero reachable vulnerabilities to pass).
  • Move release publish to softprops/action-gh-release@v3 (Node 24) on both release steps.
  • Repair self-bootstrap: installer --dir, explicit --tag for the N-1 pin, --require-minisign.
  • Validate the corpus manifest in-repo with jsonschema/v6 instead of an unpinned external schema CLI.
  • Sterile closeout: CHANGELOG.md, RELEASE_NOTES.md, docs/releases/v0.4.9.md, compare-link footers, VERSION0.4.9.

Raise the secure Go floor and preferred toolchain, refresh selected
golang.org/x modules, pin goneat and govulncheck, repair self-bootstrap
flags, move release publish to softprops/action-gh-release v3, and
validate the corpus manifest in-repo. Release docs and VERSION updated.

Role: devlead

Generated by Grok 4.5 (https://x.ai) running Grok Build (https://x.ai) under supervision of [@3leapsdave](https://github.com/3leapsdave)

Co-Authored-By: Grok 4.5 <noreply@3leaps.net>
Committer-of-Record: Dave Thompson <dave@3leaps.net> [@3leapsdave]
@3leapsdave
3leapsdave merged commit b20c22f into main Jul 29, 2026
4 checks passed
@3leapsdave
3leapsdave deleted the release/v0.4.9-package-cicd branch July 29, 2026 19:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant